Symantec report: instances of cryptojacking rose 8,500% in Q4 2017, partly due to easy-to-operate coin mining apps, coin mining up 34,000% in 2017
Where the money is, the thieves will follow — Instances of computers hijacked to mine cryptocurrency, a practice known as cryptojacking …
Context & Ripple Effects
Symantec's numbers put hard figures on a wave that had been building all quarter: [[a:926618|more than 4,200 websites, including USCourts.gov and UK NHS services, were already infected through a hacked plugin]] by February, and days after this report Krebs published a deep look at Coinhive, the JavaScript service that made hijacking visitors' CPUs nearly effortless. The 8,500% quarterly jump is what happens when coin mining apps become turnkey tools.
The arc continues through 2018: illicit mining surged another 459% year-over-year, tied partly to the leaked EternalBlue exploit, and an analysis of over 629,000 samples found at least 5% of all Monero in circulation was mined with malware — confirming Monero as cryptojacking's payout rail. By Q3, Malwarebytes saw malicious mining fall 26% even as business-targeted trojans jumped, hinting the boom was already peaking.
First-order effects
- Businesses and consumers whose machines are hijacked pay directly in degraded performance and electricity costs, while Symantec and rival security vendors see detection of coin-mining payloads become a core product requirement almost overnight.
Second-order effects
- Turnkey services like Coinhive collapse the skill barrier, pulling low-technical criminals into mining at scale and concentrating payouts in privacy coins like Monero, which becomes the de facto settlement layer for stolen hashpower.
Third-order effects
- Cryptojacking establishes passive, victim-funded revenue as a criminal business model distinct from ransomware's one-shot extortion — but Malwarebytes' Q3 decline suggests it is price-cyclical, with attackers rotating back toward direct business attacks when margins compress.
The trend: Cryptocurrency crime industrializes around whatever is easiest to monetize — first hijacked compute via turnkey mining tools, then large-scale exchange hacks — with attacker effort tracking coin prices and available exploits.